Hacker Newsnew | past | comments | ask | show | jobs | submit | halJordan's commentslogin

I'm always disheartened to find the people most loudly exclaiming the need for humanism at the same time demand that every human adopt their bespoke version of disgust, at the risk of being othered by that author.

In any event the author is free to ban whichever token they want, that's an inference time measure.


That's kind of a jump. The 2a is cool, but gun deaths outpace car deaths now and 2a people refuse literally any of the protections we have against car deaths. Whereas a 15 year old jerking it to a pornstar hurts no one and these people want to completely ban the 4th amendment.

You're not the only one, and youre not a part of the stupidest conspiracy in the world, but you better hope the flat eartherers dont walk in

Tls 1.3 is completely banned by the gfw

Why is TLS 1.3 interesting here, in relation to censorship circumvention? Why is version 1.3 banned and not 1.2?

TLS 1.3 forces PFS, which means that if you want to decrypt a 1.3 stream, you have to actually do a man in the middle attack, not just get a copy of a key. PFS was optional before.

It supports ECH, which lets you hide which service the client is trying to reach on a multitenant host or CDN. Given that Cloudflare supports ECH, and that it's possible to hide the fact that you're using ECH, that makes it possible to have connections that could actually be using any of a huge number of possible sites without passive spying equipment being able to tell which ones.

It removes a bunch of weak old primitives and options, and should generally be harder to misconfigure in a dangerous way.


Thanks a lot for the detailed reply!

Just in case someone will read this without knowing the abbreviations:

PFS = perfect forward secrecy [0]

ECH = Encrypted Client Hello

[0] https://en.wikipedia.org/wiki/Forward_secrecy

[1] https://en.wikipedia.org/wiki/Server_Name_Indication#Encrypt...


That has nothing to do with the guy who said stop anthropomorphizing llms and then proceeded to anthropomorphize an llm.

This is exactly the sort of refusal to comprehend so that you can get in an "um, ackshually" that the op is talking about. He's quoting a line from a book as a metaphor for a concept the book illustrates well.

You see someone who you think has missed a larger point, and all you can muster as a reply is a vague jab and unexplained reference? Do you not see the irony? Your whole comment is an “um, ackshually”, the very thing you are decrying.

I didn’t enjoy Dune, by the way. No shade on those who did, of course, but I couldn’t bring myself to finish it.

If you think there’s something there, explain your point. Make an argument. Maybe I have misunderstood something and will correct my thinking, or maybe you have misunderstood and will correct yours. But as it is, I don’t see your comment as providing any value to the discussion. It’s the equivalent of a hit and run, meant to insult the other person while remaining uncommitted enough to shield yourself from criticism.


This guy gets it.

Yes, latexr managed to somehow sidestep the point entirely and make a pedantic correction. I notice this a lot in these discussions.

The point is AI has lots of useful applications, even though there's also lots of detestable ones.


Lol what? This site gets off so hard on reminding everyone that the north won and we're no longer a federal union or anything other than a unitary state controlled by the northeast

You're upset that an encrypted stream needs encryption keys? And that you need physical access, the binaries themselves, and reverse engineering tools to get them?

I think you'll be surprised to learn you can do the same thing to any program which encrypts data


No, I’m not upset. Private keys are necessary, that’s fine. Vivotek encrypts them additionaly, but stores the encryption keys right next to the encypted data.

One could use TPM chip to store the keys, rather than such useless obscure encryption, which looks secure, but it’s not.


You're confusing two different initiatives (which is the point)

This has been Apple's stance for years and has been routinely brought down in courts across the globe. Why are you guys surprised.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: